EDBT 2026 Demo / reviewers in the wild / expert
Xunjin Zheng
dblp:358/8889
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0002-8146-4861ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Program synthesis and code generation · 61% Program analysis · 30% Programming languages and type systems · 9% | |
| Network and information security
1 paper |
Systems and software security · 100% | |
| Artificial intelligence
1 paper |
Efficient and distributed learning · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › software vulnerability
deserialization vulnerability |
0.8 | 1 | 2024 | GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024 |
Program synthesis and code generation
code completion |
0.8 | 1 | 2024 | RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024 |
Program synthesis and code generation › code completion
repository-level code completion |
0.8 | 1 | 2024 | RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024 |
Program analysis
static analysis |
0.8 | 1 | 2024 | GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024 |
Machine learning › Efficient and distributed learning › inference efficiency
LLM inference optimization |
0.2 | 1 | 2024 | RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024 |
Programming languages and type systems › language semantics
dynamic semantics |
0.2 | 1 | 2024 | GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024 |
Methods — techniques the papers use, named apart from their topics
static analysis · 1.5language model · 1.5context-aware selection · 1.5class relation graph · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language ModelsabstractThe success of language models in code assistance has spurred the proposal of repository-level code completion as a means to enhance prediction accuracy, utilizing the context from the entire codebase. However, this comprehensive context comes at a cost: while it enhances model performance, it also increases inference latency. This balance between improved accuracy and computational efficiency poses a significant challenge in real-world applications. We present RepoGenix, a solution that enhances repository-level code completion without increased latency. RepoGenix combines analogous context and relevant context, using Context-Aware Selection technology to efficiently compress these contexts into limited-size prompts. Our experiments on CrossCodeEval demonstrate that RepoGenix not only achieves a substantial 48.41% reduction in inference time, but also yields improvement in performance compared to baseline methods. We have successfully implemented and tested RepoGenix within AntGroup's development environments. This approach is being extended to multiple programming languages and will be open-sourced, aiming to enhance code completion efficiency for the broader developer community. Xiaoheng Xie, Gehao Zhang, Xunjin Zheng, Peng Di, Wei Jiang 0041, Chengpeng Wang 0001, Gang Fan |
ASE | 4 |
| 2024 | GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language DeserializationabstractDuck typing is a flexible programming style in dynamic languages, enabling the achievement of complex behaviors using less code. The use of duck typing is currently widespread; however, the question is whether its use in code is truly safe. In fact, improper use of duck typing may introduce unexpected security threats. In this paper, we reveal another side of duck typing, showing how it can exacerbate the impact of deserialization vulnerabilities and expand the range of attack options for attackers. We present three cases of duck typing misuse and theoretically demonstrate how such misuse can expand the attack surface of deserialization vulnerabilities. Additionally, we design a static analysis tool, GrayDuck, to construct a Class Relation Graph (CRG) that clearly delineates the range of classes accessible through each deserialization operation and identify instances of duck typing misuse along with the associated attack surfaces so that to assess the potential harm. We utilized this tool to scan 5 Python programs known to have real deserialization vulnerabilities, detecting 7 issues of deserialized object duck typing misuse and calculating the corresponding expansions of the attack surfaces. Xunjin Zheng, Cai Fu, Xiaoheng Xie, Peng Di |
ASE | 2 |